OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Organization: info@thehackernews.com (The Hacker News)

Location: Global

Source: info@thehackernews.com (The Hacker News)

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet’s own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and

Apply / Read More


WhatsApp
Get Latest Updates: Join our WhatsApp Group

Scroll to Top